CVE-2019-14697
published 2019-08-06CVE-2019-14697: musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.70%
84.3th percentile
musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | musl | < musl 1.1.23-2 (bookworm) | musl 1.1.23-2 (bookworm) |
| musl-libc | musl | >= 0 < 1.1.23-2 | 1.1.23-2 |
| musl-libc | musl | >= 0 < 1.1.23-2 | 1.1.23-2 |
| musl-libc | musl | >= 0 < 1.1.23-2 | 1.1.23-2 |
| musl-libc | musl | >= 0 < 1.1.23-2 | 1.1.23-2 |
| musl-libc | musl | >= 0 < 0.9.15-1ubuntu0.1~esm2 | 0.9.15-1ubuntu0.1~esm2 |
| musl-libc | musl | >= 0 < 1.1.9-1ubuntu0.1~esm3 | 1.1.9-1ubuntu0.1~esm3 |
| musl-libc | musl | >= 0 < 1.1.19-1ubuntu0.1~esm1 | 1.1.19-1ubuntu0.1~esm1 |
| musl-libc | musl | >= 0 < 1.1.24-1ubuntu0.1~esm1 | 1.1.24-1ubuntu0.1~esm1 |
| musl-libc | musl | 0.9.12 – 1.1.23 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
musl vulnerabilities
osv·2023-03-31·CVSS 9.8
CVE-2019-14697 [CRITICAL] musl vulnerabilities
musl vulnerabilities
It was discovered that musl did not handle certain i386 math functions
properly. An attacker could use this vulnerability to cause a denial of
service (crash) or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS.
(CVE-2019-14697)
It was discovered that musl did not handle wide-character conversion
properly. A remote attacker could use this vulnerability to cause resource
consumption (infinite loop), denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04
ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-28928)
GHSA
GHSA-x5qg-pw5v-r37v: musl libc through 1
ghsa_unreviewed·2022-05-24
CVE-2019-14697 [CRITICAL] CWE-787 GHSA-x5qg-pw5v-r37v: musl libc through 1
musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.
OSV
CVE-2019-14697: musl libc through 1
osv·2019-08-06·CVSS 9.8
CVE-2019-14697 [CRITICAL] CVE-2019-14697: musl libc through 1
musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.
Ubuntu
musl vulnerabilities
vendor_ubuntu·2023-03-31·CVSS 9.8
CVE-2020-28928 [CRITICAL] musl vulnerabilities
Title: musl vulnerabilities
Summary: Several security issues were fixed in musl.
It was discovered that musl did not handle certain i386 math functions
properly. An attacker could use this vulnerability to cause a denial of
service (crash) or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS.
(CVE-2019-14697)
It was discovered that musl did not handle wide-character conversion
properly. A remote attacker could use this vulnerability to cause resource
consumption (infinite loop), denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04
ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-28928)
Instructions: In general, a standard system update will make all the neces
Debian
CVE-2019-14697: musl - musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, r...
vendor_debian·2019·CVSS 9.8
CVE-2019-14697 [CRITICAL] CVE-2019-14697: musl - musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, r...
musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.
Scope: local
bookworm: resolved (fixed in 1.1.23-2)
bullseye: resolved (fixed in 1.1.23-2)
forky: resolved (fixed in 1.1.23-2)
sid: resolved (fixed in 1.1.23-2)
trixie: resolved (fixed in 1.1.23-2)
No detection rules found.
No public exploits indexed.
2019-08-06
Published